Identity Proofing via Risk Engine Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Digital transactions are often compromised by unauthorized or malicious actors, particularly in hostile environments resulting from Denial of Service (DOS) attacks, leading to fraudulent activities and unauthorized access.
Innovation Solution
A system utilizing AI/ML capabilities in a smart data hub and risk engine for identity proofing, which captures user registration information, monitors sessions, reviews egocentric and allocentric factors, and uses out-of-band methods to verify user identities, determining threat classification and risk scores to ensure secure access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional authentication methods are used, then ease of operation is maintained, but security and reliability deteriorate due to unauthorized access and fraudulent transactions
Solution Approach 1:
The system performs preliminary identity proofing and validation before granting access. The risk engine pre-evaluates user entities by analyzing egocentric and allocentric factors, reviewing submitted evidence, and contacting third parties in advance of the actual transaction or access attempt. This preliminary action ensures that only verified users proceed to the actual operation, maintaining security without burdening legitimate users during the critical transaction moment.
Solution Approach 2:
The risk engine acts as an intermediary between the user entity and the relying party system. It mediates the authentication process by independently evaluating risk factors, contacting third parties for verification, and making access decisions based on the synthesized risk assessment. This intermediary layer protects the core system from direct exposure to potentially malicious users while maintaining a streamlined interface for legitimate users.
2Reliability
If comprehensive validation and verification steps are implemented, then security is improved, but processing time and device complexity increase
Solution Approach 1:
Identity proofing and evidence validation are performed in advance during registration or onboarding phases. The risk engine contacts third parties, verifies user identities, and establishes baseline risk profiles before users need to access the system. This preliminary validation reduces verification time during actual transactions while maintaining comprehensive security checks.
Solution Approach 2:
The system dynamically adjusts the depth and scope of verification based on risk parameters. For low-risk users with established profiles, the system can streamline verification steps. For high-risk or new users, more comprehensive checks are performed. This parameter-based approach allows the system to maintain high security standards while optimizing processing time based on individual risk assessments.
3Measurement precision
If AI/ML capabilities are integrated for threat detection, then measurement precision of threat identification is improved, but device complexity increases
Solution Approach 1:
The risk engine with AI/ML capabilities serves as a specialized intermediary component that handles the complexity of threat detection. Rather than distributing AI/ML complexity throughout the entire system, the risk engine consolidates these advanced analytical functions in a dedicated module. This intermediary approach maintains high threat detection accuracy while containing architectural complexity in a specific, manageable component.
Solution Approach 2:
The risk engine performs multiple functions including traditional risk assessment, AI/ML-based threat detection, evidence validation, and third-party coordination. By consolidating these diverse functions in a single multi-functional component, the system achieves high measurement precision for threat identification without proportionally increasing overall device complexity. The universal risk engine handles various verification tasks that would otherwise require separate specialized systems.
Data Source
AI summary
The system and method disclosed performs entity authentication through identification proofing. A relying party such as a corporation or other type of entity having a secure website, computer network and secure facility working a risk engine can determine the authenticity, validation and verification during registration of a user entity. The identification proofing is integrated with a risk engine. The risk engine is capable of using bio-behavior based information which may be continuously monitored.


